rights-explainer

Pass

Audited by Gen Agent Trust Hub on Mar 23, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill functions as an autonomous auditor for legal aid portals and information systems, evaluating them for plain-language quality and legal accuracy.\n- [COMMAND_EXECUTION]: The skill reads standard dependency and configuration files (e.g., package.json, requirements.txt, go.mod) to identify the platform's tech stack and search infrastructure. This is standard behavior for an analysis agent.\n- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface because it processes untrusted data from the analyzed codebase (HTML, markdown, database records). However, it lacks high-risk capabilities such as network access or administrative shell access. Ingestion points: codebase and legal content files. Boundary markers: absent. Capability inventory: local file read and local telemetry file append. Sanitization: absent.\n- [DATA_EXFILTRATION]: No network communication or exfiltration of sensitive information was detected.\n- [SAFE]: The skill contains a telemetry feature that appends execution metadata to a local file in the project memory directory (~/.claude/projects/skill-telemetry.md). This is a restricted local write operation for performance tracking.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 23, 2026, 10:58 AM
Security Audit — agent-trust-hub — rights-explainer